Gotorex Security & Responsible Disclosure Policy

Effective Date: 21 August 2026
Last Updated: 21 August 2026

This Security & Responsible Disclosure Policy applies to www.gotorex.com, a multi-seller international e-commerce marketplace operated from South Africa.

Gotorex Business Address:
<span style="color:red">[INSERT FULL REGISTERED BUSINESS ADDRESS, SOUTH AFRICA]</span>

Security & Legal Contact: admin@gotorex.com

Gotorex takes the security of its website, marketplace, customer information and seller information seriously. This Policy explains how security concerns may be reported and how Gotorex may respond.

1. Our Security Commitment

Gotorex aims to use reasonable technical and organisational safeguards to protect its systems and information against:

  • Unauthorised access;
  • Loss or misuse of information;
  • Unauthorised alteration;
  • Destruction;
  • Fraud; and
  • Other reasonably foreseeable security threats.

No website, system or transmission over the internet can be guaranteed to be completely secure.

2. Responsible Disclosure

Security researchers and other individuals are encouraged to report genuine security vulnerabilities responsibly.

Reports should be sent to:

admin@gotorex.com

Please provide enough information for Gotorex to understand and reproduce the reported issue.

Where reasonably possible, include:

  • A description of the vulnerability;
  • The affected website, page or feature;
  • Steps required to reproduce the issue;
  • Potential security impact;
  • Screenshots or other non-sensitive evidence; and
  • Your contact information for follow-up.

3. Responsible Testing

Security testing must be conducted responsibly and only to the extent reasonably necessary to demonstrate a vulnerability.

Researchers must not:

  • Access, copy or disclose unnecessary personal information;
  • Access another person's account without permission;
  • Modify or delete data;
  • Disrupt or degrade Gotorex systems;
  • Conduct denial-of-service attacks;
  • Use malware;
  • Conduct social engineering against Gotorex personnel or customers;
  • Attempt to obtain payment information;
  • Extort or threaten Gotorex;
  • Publicly disclose a vulnerability before allowing reasonable time for investigation; or
  • Continue testing after Gotorex has requested that testing stop.

Testing must not intentionally interfere with customers, sellers, suppliers or other users.

4. Personal Information

If a security vulnerability exposes personal information, researchers must avoid collecting, retaining, copying or disclosing more information than reasonably necessary to demonstrate the issue.

Any personal information obtained accidentally should be securely deleted as soon as reasonably practicable.

Security incidents involving personal information may be handled in accordance with applicable data-protection and breach-notification laws.

5. What to Report

Security concerns may include:

  • Unauthorised access vulnerabilities;
  • Authentication or authorisation weaknesses;
  • Exposure of sensitive information;
  • Payment-security vulnerabilities;
  • Account-takeover vulnerabilities;
  • Significant software vulnerabilities;
  • Security misconfigurations; or
  • Other vulnerabilities that could materially affect Gotorex users or systems.

6. Issues Generally Outside This Policy

The following may not qualify as security vulnerabilities unless they create a demonstrable material security risk:

  • Spam;
  • Social-engineering attempts against third parties;
  • Self-inflicted account issues;
  • Reports without sufficient information to investigate;
  • General website feedback;
  • Automated vulnerability scans that create excessive traffic;
  • Known third-party vulnerabilities outside Gotorex's control; or
  • Theoretical issues without a reasonably demonstrated security impact.

7. Gotorex's Response

Gotorex may:

  • Acknowledge a report;
  • Investigate the issue;
  • Request additional information;
  • Take corrective action;
  • Restrict affected functionality;
  • Work with affected sellers or service providers;
  • Notify affected individuals where legally required; and
  • Report matters to competent authorities where required or appropriate.

Response and remediation times may vary according to the severity and complexity of the issue.

8. Confidentiality & Disclosure

Researchers should provide Gotorex with reasonable time to investigate and address a vulnerability before publicly disclosing technical details.

Gotorex may communicate with researchers regarding remediation where appropriate.

Nothing in this Policy prevents a person from exercising rights that cannot legally be waived or restricted.

9. Security Incidents

If Gotorex becomes aware of a security incident, it may take reasonable steps to contain, investigate and remediate the incident.

Where legally required, Gotorex may notify:

  • Affected customers;
  • Sellers;
  • Business partners;
  • Regulators;
  • Law-enforcement authorities; or
  • Other appropriate parties.

Notification requirements depend on the nature of the incident and applicable law.

10. Account Security

Customers and sellers are responsible for maintaining the security of their accounts, including:

  • Keeping passwords confidential;
  • Using appropriate account-security measures;
  • Not sharing login credentials; and
  • Reporting suspected unauthorised account activity promptly.

Suspected account compromise should be reported to:

admin@gotorex.com

11. Payment Security

Payment information may be processed by third-party payment providers.

Gotorex may not directly store or process all payment-card information and may rely on specialised payment providers and security controls.

Customers should never send full payment-card numbers, passwords, authentication codes or other sensitive credentials by email.

12. Third-Party Services

Gotorex may use third-party providers for services such as:

  • Payments;
  • Hosting;
  • Shipping;
  • Analytics;
  • Security;
  • Communications; and
  • Marketplace functionality.

Security practices of third parties may be governed by their own policies and contractual obligations.

Gotorex may take reasonable steps to select and manage service providers appropriate to the nature of the services provided.

13. Fraud & Abuse

Gotorex may monitor transactions and account activity for legitimate security, fraud-prevention and compliance purposes.

Where reasonably necessary and legally permitted, Gotorex may:

  • Restrict accounts;
  • Delay transactions;
  • Cancel transactions;
  • Request verification;
  • Restrict seller activity; or
  • Report suspected unlawful activity.

14. Damaged Products, Returns & Refunds

Security reports should not be sent through product-return or refund channels.

For damaged products, returns or refund requests, customers should contact:

admin@gotorex.com

Customers may be required to provide reasonable evidence, including photographs, videos, order information or other relevant documentation.

Where inspection is required, the time required to investigate and resolve the matter depends on the circumstances and complexity of the case, subject to mandatory legal requirements.

15. Shipping & Security

Shipping times vary according to the seller, supplier, warehouse, carrier and destination.

Some products may be delivered as quickly as 1–3 business days in countries such as the United States, while other products may take substantially longer.

Security, customs or fraud checks may occasionally affect processing or delivery where legally permitted.

16. No Guarantee

Although Gotorex takes reasonable security measures, no online service can guarantee complete protection against every security threat.

Customers and sellers acknowledge that internet-based services involve inherent security risks.

This does not exclude any mandatory legal obligations imposed on Gotorex.

17. Policy Changes

Gotorex may update this Policy as its security practices, technology, marketplace or legal requirements change.

The latest version will be published on www.gotorex.com.

18. Contact & Responsible Disclosure

Gotorex
Security Email: admin@gotorex.com

Business Address:
<span style="color:red">[INSERT FULL REGISTERED BUSINESS ADDRESS, SOUTH AFRICA]</span>

Website: www.gotorex.com